Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Networking

    Business Continuity Best Practices

    Written by

    Andrew Garcia
    Published November 7, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The usual end-of-summer string of catastrophic weather-related disasters, combined with an incredibly turbulent economy, should have tech implementers looking more closely at the plans they have in place to survive the unexpected-no matter what the source.

      Enterprise IT managers need to look beyond the technical side of things, mapping out the core elements of the business to help plan for the unfathomable. At the same time, they need to take advantage of newly burgeoning standardization and certification of business continuity practices.
      Business continuity management, or BCM, describes the organized framework for building a company’s defenses against potential threats, whether those threats are financial, technical, social, political or environmental in nature.
      Through BCM, a business identifies the core processes in need of protections; anticipates potential threats to those processes (and, therefore, the company and its financial backers); predicts the potential impact of these threats on the way the company does business; clearly defines processes to remediate or work around those problems; and establishes methodologies for both testing and improving these remediation steps over time.
      With these plans in place, a company should ultimately be able to continue business operations at levels deemed acceptable by the planning committee before the onset of disaster.
      There are many different ways to go about building this level of resiliency into corporate practices and processes. Indeed, a BCM plan needs to be tailored toward the philosophy of the company, its tolerance for risk and the company’s long-term goals. However, the plan needs to be grounded in enough measurable goals and consistent practices that it can be compared and contrasted with other companies’ efforts to extend the security afforded by the plan to external entities. A BCM plan can provide only a limited amount of resiliency if worldwide facilities, supply chain partners or global affiliates are not holding themselves to the same standards in their continuity planning.
      To provide this level of assurance to these external entities, a BCM standard becomes a critical element. Such a standard provides a way to measure and contrast your efforts with that of others, thereby allowing you to extend your organization’s philosophy to those external relationships-and helping extend the company’s ability to meet regulatory and customer requirements.
      This kind of extensibility beyond corporate borders could become a significant competitive advantage for a company if the compatibility is proven through some kind of certification. The certification would allow that company to quickly prove to partners and affiliates that it meets a certain standard when it comes to continuity planning.
      “Business continuity is designed to allow an organization to interrogate its processes so it understands how things work-where the risk points are and how to start building mitigation processes and strategies,” said Todd VanderVen, president of BSI Management Systems, America. Certification “gives you the ability to do the audit and certification of those processes, so when you are out talking to the supply chain, you can ask them if they follow business continuity. They can say yes, but if it is not a certified type of process, you never really know,” added VanderVen.

      Read about how to develop an effective and timely notification process here.

      Unfortunately, one danger of a poorly drawn-out BCM standard is homogeneity. What works for one company may not be a good fit for another. Every company undergoing a BCM initiative must make sure that the strategy fits the ongoing interests of the company and its shareholders, is in line with the company’s risk tolerance, and is actually achievable given the amount of manpower and budget allocated for the initiative. Therefore, a well-designed standard has to be generic enough in its guidance to allow companies of all shapes and missions to operate within its strictures, while maintaining enough of itself to achieve its stated purpose.

      The corporate officials in charge of implementing BCM must also recognize that there really is no end game for a proper BCM initiative. The plan must constantly undergo evaluation and testing to ensure it meets the needs of the company, while adapting to changing business conditions. Without a defined process to evolve the plan, it can quickly fall out of date. It may provide the benefit of keeping auditors at bay, but may not be effective when actual emergent conditions arise.

      Whats Out There Now

      Last year, title ix of public law 110-53 tasked the Department of Homeland Security to take the lead in developing, implementing and administering a voluntary certification program for BCM in the private sector, moving to help define a de facto standard in the process. The DHS has not yet recommended a standard to fit this voluntary certification program, and the guidance the agency provides to help a company plan for disaster on the DHS Ready.gov Web site does not match the scope necessary for a full-fledged BCM initiation, let alone a certification program.
      At this time, the only auditable BCM standard available that can help C-level executives fully identify and make more resilient the processes in need of protection is the British Standard Institution’s BS 25999.
      Celebrating its first birthday in November, BS 25999 is actually composed of two distinct documents (available for purchase).
      Part one is a code of practice that lays out the terminology, scope and objectives of a BCM scheme, while part two comprises the actual specification that enumerates the steps that need to be taken to meet business goals. Part two is therefore intended to be auditable and certifiable, providing the basis of comparison needed to extend the relationship externally.
      Third-party providers-such BSI Management Systems-currently perform the certification testing, while others – such as Avalution – provide consulting services to help kick-start a BCM pilot or guide a growing iteration’s development.
      These and other providers can come in to provide impartial and objective guidance and strategies, helping to deliver their clients to the certification stage. Ultimately, however, the DHS has charged the American National Standards Institute’s American Society for Quality National Accreditation Board, or ANAB, with administering the certification program, so the certification processes provided by providers such as BSI Management Systems may need to evolve as time goes on.
      However, BSI Management Systems officials are quick to point out that companies do not have to certify their BS 25999 implementation to reap tangible benefits.
      “You can bring [BCM] into the organization as a best practice to start the process of interrogating where the key processes and people are, and to establish what to do to maintain sustainability in the organization,” said VanderVen.
      He added that planning with an eye toward BS 25999 also helps business leaders understand their companies better.
      “BS 25999 causes an organization to begin a journey into what their processes really are, but may not necessarily be evident,” VanderVen said. “We’ve had customers come to us who thought they had 80 different activities that they thought they needed to track, but it turns out there were 18 core processes that really made a difference in their business. Then they were able to distill down to make sure those 18 key processes were maintainable and protected.”
      While BS 25999 is a globally recognized standard (and one that the DHS recognizes), projects nonetheless are under way to establish a U.S. standard for BCM. Officials with information security company ASIS International, for example, recently notified ANSI that it would begin work on a new BCM standard.

      According to VanderVen, the British Standards Institution is working with ASIS on the development of this standard, with development slated to begin this month. VanderVen anticipates that ASIS will largely utilize BS 25999 at its base, with the intention of the new proposal becoming an ISO (International Organization for Standardization) standard two or three years down the road.
      ??
      eWEEK Labs Senior Technical Analyst Andrew Garcia can be reached at agarcia@eweek.com.

      Andrew Garcia
      Andrew Garcia
      Andrew cut his teeth as a systems administrator at the University of California, learning the ins and outs of server migration, Windows desktop management, Unix and Novell administration. After a tour of duty as a team leader for PC Magazine's Labs, Andrew turned to system integration - providing network, server, and desktop consulting services for small businesses throughout the Bay Area. With eWEEK Labs since 2003, Andrew concentrates on wireless networking technologies while moonlighting with Microsoft Windows, mobile devices and management, and unified communications. He produces product reviews, technology analysis and opinion pieces for eWEEK.com, eWEEK magazine, and the Labs' Release Notes blog. Follow Andrew on Twitter at andrewrgarcia, or reach him by email at agarcia@eweek.com.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×